CVE-2026-40976
published 2026-04-28CVE-2026-40976: In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable…
PriorityP358critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.49%
38.7th percentile
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
| vmware | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Boot up to 4.0.5 Health authorization
vuldb·2026-04-28·CVSS 9.1
CVE-2026-40976 [CRITICAL] Vmware Spring Boot up to 4.0.5 Health authorization
A vulnerability was found in Vmware Spring Boot up to 4.0.5. It has been rated as critical. This issue affects some unknown processing of the component Health Handler. The manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-40976. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
ghsa·2026-04-28
CVE-2026-40976 [CRITICAL] CWE-862 Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Red Hat
Spring Boot: Spring Boot: Security bypass due to ineffective default web security
vendor_redhat·2026-04-27·CVSS 9.1
CVE-2026-40976 [CRITICAL] CWE-305 Spring Boot: Spring Boot: Security bypass due to ineffective default web security
Spring Boot: Spring Boot: Security bypass due to ineffective default web security
A flaw was found in Spring Boot. Under specific conditions, including being a servlet-based web application without custom Spring Security configuration and relying on the default web security filter chain, a remote attacker could bypass security. This allows unauthorized access to all application endpoints, leading to potential information disclosure and circumvention of security controls.
Statement: This is an Important flaw in Spring Boot that allows security bypass under specific application configurations. When a servlet-based web application lacks custom Spring Security configuration, relies on the default web security filter chain, depends on `spring-boot-actuator-autoconfigure`, and does not include
No detection rules found.
No public exploits indexed.
2026-04-28
Published